A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flatpress
Flatpress flatpress |
|
CPEs | cpe:2.3:a:flatpress:flatpress:1.3.1:*:*:*:*:*:*:* | |
Vendors & Products |
Flatpress
Flatpress flatpress |
Mon, 24 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Mon, 24 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-24T00:00:00.000Z
Updated: 2025-02-24T16:52:23.129Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25460

Updated: 2025-02-24T16:51:41.927Z

Status : Analyzed
Published: 2025-02-24T16:15:14.873
Modified: 2025-06-12T20:14:41.587
Link: CVE-2025-25460

No data.